Iran's ransomware proxies and the collapse of the line between crime and state power- 217
May 17, 2026
Since 2020, a pattern has hardened into doctrine: when Iran wants to pressure an adversary's critical infrastructure without owning the consequences, it reaches for a ransomware crew rather than a uniformed cyber unit. What began as an isolated 2020 attempt to disrupt Israeli water systems has, by 2026, become a coordinated ecosystem — DragonForce, Handala, Pay2Key, and personas like CyberAv3ngers operating as deniable extensions of state intent, blurring the line between criminal extortion and geopolitical coercion so thoroughly that threat intelligence teams now rely on timing and targeting patterns, not clean attribution, to tell the two apart.
The escalation has a clear rhythm. Ransomware first became "meaningful" as cover for coercive activity around 2020–2021, according to Georgianna Shea of the Foundation for Defense of Democracies. By 2023 it functioned openly as a coercive tool, and after October 2023 — with the wider regional conflict intensifying — activity intersected decisively with critical infrastructure targeting, ransomware-as-a-service ecosystems, and direct PLC and OT disruption. Dragos analyst Abdul Alamri points to incidents like the Handala Hack — Iranian-linked and tracked internally as TAT26-14 — where compromise of identity and endpoint infrastructure enabled enterprise-scale disruption without ever touching operational technology directly. That distinction matters: the risk to industrial systems increasingly arrives sideways, through IT compromise that degrades visibility and recovery, rather than through direct manipulation of control systems.

What makes attribution genuinely difficult is not sloppy analysis but a deliberate architectural choice. Iranian-aligned actors, per Shea, use ransomware groups as gray-zone instruments — brokering victim access, borrowing criminal infrastructure for tooling, and disguising coercive operations as ordinary extortion. U.S. and Israeli-aligned cyber activity, by contrast, tends to stay within formal military, intelligence, and regulatory channels. The asymmetry is the point: irregular warfare through proxies creates effect without exposing the state actor pulling the strings. The Shamir Medical Center case is instructive here — an intrusion first attributed to an Eastern European ransomware group was later reassessed by Israeli officials as Iranian. In OT environments, CPX's Saltanat Mashirova notes, this ambiguity is compounded further: sensor or actuator manipulation can look indistinguishable from ordinary equipment failure.
The sectors bearing this pressure are consistent across every analyst consulted — water and wastewater, energy, manufacturing, transportation, and healthcare, with particular emphasis on internet-facing PLCs, HMIs, and the serial-to-Ethernet conversion points that expose low-level control devices to routable networks. Shea frames the strategic logic precisely: the intent is coercive disruption and pre-positioned escalation capability, engineered to manipulate physical processes without generating the network evidence defenders are trained to look for.

The industrial response, where it exists, has shifted in character rather than intensity. Rather than betting entirely on prevention, operators in Israel and the U.S. are increasingly building for resilience — assuming compromise, and asking instead whether operations can continue and recover quickly. Amit Hammer of Salvador Technologies frames this as recognition that OT recovery is categorically different from IT recovery: restoring a file server solves nothing if an engineering workstation or SCADA server needs a clean, tested, bootable recovery path of its own. Government guidance — CISA's advisories on PLC disconnection and multifactor authentication, its Cybersecurity Performance Goals — is improving but still lags the tempo the conflict demands. The gap, as Shea puts it, sits at the lowest level of the stack: sensors and actuators built decades ago with no authentication, no logging, and no way to prove after the fact that they weren't manipulated.